Cisco Systems, Inc 170 West Tasman Drive San Jose, CA
Americas Headquarters
Installing and Configuring Cisco Access Registrar
November
Copyright 2007 Cisco Systems, Inc. All rights reserved
Installing and Configuring Cisco Access Registrar
License Slabs
C O N T E N T S
Overview
Cisco.com
3-12
Using pkgrm to Remove Cisco Access Registrar Solaris Software
3-11
3-12
Using aregcmd
Installing Cisco Access Registrar Software from CD-ROM
Using a Script to Determine Service
Creating and Setting Group Membership
Creating a RemoteServer
Installing and Configuring Cisco Access Registrar
Configuring Session Management
Configuring Session Management
Contents
Contents Installing and Configuring Cisco Access Registrar
viii
OL-17221-02
Obtaining Documentation
About This Guide
Cisco.com
For Emergencies only - security-alert@cisco.com
Reporting Security Problems in Cisco Products
Documentation Feedback
Cisco Product Security Overview
Cisco Technical Support & Documentation Website
Obtaining Technical Assistance
http//tools.cisco.com/RPF/register/register.do
Definitions of Service Request Severity
Submitting a Service Request
xiii
Obtaining Additional Publications and Information
About This Guide
Installing and Configuring Cisco Access Registrar
OL-17221-02
C H A P T E R
Installation Dialog Overview
Installation Type
Overview
Open Database Connectivity
Installation Location
License File Location
Java 2 Runtime Environment
Base Directory
Downloading Cisco Access Registrar Software
Example Configuration
Continue with Installation
CSCOar-4.2.1-sol10-k9.tar.gz for Solaris
Cisco Access Registrar 4.2 Licensing
Description
Getting Cisco Access Registrar 4.2 License
License Slabs
Product
opt/CSCOar/bin/arserver restart
Installing Cisco Access Registrar 4.2 Licenses
Adding Additional Cisco Access Registrar 4.2 Licenses
Sample License File
aregcmd -l directoryname
aregcmd Command-Line Option
Displaying License Information
Launching aregcmd
Installing and Configuring Cisco Access Registrar
Chapter 1 Overview Cisco Access Registrar 4.2 Licensing
OL-17221-02
Installing Cisco Access Registrar 4.2 Software on Solaris, page
Installing Cisco Access Registrar
Installing the Cisco Access Registrar 4.2 License File
Installing the Cisco Access Registrar 4.2 License File, page
Deciding Where to Install
Deciding Where to Install
Installing Cisco Access Registrar Software from CD-ROM
Installing Downloaded Software
pkgadd -d /tmp CSCOar
Common Solaris Installation Steps
Step 5 Proceed to Common Solaris Installation Steps
zcat CSCOar-4.2.1-sol9-K9.tar.gz tar xvf
Step 9 Enter the directory or mount point where the J2RE is installed
Installing Cisco Access Registrar 4.2 Software on Solaris
Step 13 Enter Y to install the setuid/setgid files
Step 14 Enter Y to continue with the software installation
Chapter 2 Installing Cisco Access Registrar
RPC Bind Services
Installing Cisco Access Registrar 4.2 Software on Linux
Installing Cisco Access Registrar on LDoms
Configuring SNMP
cd /cdrom/cdrom0/kit/linux-2.4
Common Linux Installation Steps
cp CSCOar-4.2.1-lnx26-install-K9.sh /tmp
chmod 777 CSCOar-4.2.1-lnx26-install-K9.sh
Copyright C
CSCOar-4.2.1-lnx26-install-k9.sh
Build Date Mon Nov 03 235551
Build Host spencer.cnslab.cisco.com
Installing and Configuring Cisco Access Registrar
Configuring SNMP
Chapter 2 Installing Cisco Access Registrar
Installing Cisco Access Registrar 4.2 Software on Linux
Installing and Configuring Cisco Access Registrar
2-10
Chapter 2 Installing Cisco Access Registrar
Installing Cisco Access Registrar 4.2 Software on Linux
Installing the Cisco Access Registrar License File, page
Solaris Software Upgrade Overview
Solaris Software Upgrade Overview, page
Linux Software Upgrade Overview, page Software Upgrade Tasks, page
etc/init.d/arserver restart
Linux Software Upgrade Overview
See Using pkgrm to Remove Cisco Access Registrar Solaris Software
cd /opt mv AICar1 CSCOar
etc/init.d/arserver restart
Software Upgrade Tasks
Disabling Replication
cd /radius/replication
Removing the AICar1 Package
Using pkgrm to Remove Cisco Access Registrar Solaris Software
pkgrm AICar1
Software Upgrade Tasks
Removing the CSCOar Package
pkgrm CSCOar
Chapter 3 Upgrading Cisco Access Registrar Software
cd /opt/CSCOar/bin uninstall-ar
Using uninstall-ar to Remove Linux Software
Installing Cisco Access Registrar Software from CD-ROM, page
Installing the Cisco Access Registrar License File
Upgrading Cisco Access Registrar Solaris Software
Deciding Where to Install, page
Common Solaris Installation Steps
zcat CSCOar-4.2.1-sol9-k9.tar.gz tar xf
Installing Cisco Access Registrar Software from CD-ROM
Installing Downloaded Software
Step 1 For a full install, press Enter
Step 10 Enter Y to continue with the software installation
3-10
Step 7 Enter the administrator userID and password
Step 9 Enter Y to install the setuid/setgid files
If you choose not to use the SNMP features of CAR, the installation process is completed. To use SNMP features, complete the configuration procedure described in Configuring SNMP
Back-up Copy of Original Configuration
3-11
Configuring SNMP
Removing Old VSA Names
VSA Update Script
3-12
opt/CSCOar/data
Upgrading Cisco Access Registrar Linux Software
Using uninstall-ar to Remove Linux Software, page
Common Linux Installation Steps, page
cd /cdrom/cdrom0/kit/linux-2.6
uninstall-ar
cp CSCOar-4.2.1-lnx26-install-k9.sh /tmp
cd /opt/CSCOar/bin arserver stop
Common Linux Installation Steps
chmod 777 CSCOar-4.2.1-lnx26-install-k9.sh
CSCOar-4.2.1-lnx26-install-K9.sh
3-15
directory where it is installed
3-16
Preparing
Backup Copy of Original Configuration
3-17
opt/CSCOar/jakarta-tomcat-4.0.6/webapps/tomcat-docs/ssl-howto.html
Upgrading Cisco Access Registrar Linux Software
3-18
VSA Update Script
Chapter 3 Upgrading Cisco Access Registrar Software
Configuring SNMP
Configuring SNMP
Restarting Replication
3-19
Restarting Replication
3-20
Chapter 3 Upgrading Cisco Access Registrar Software
Installing and Configuring Cisco Access Registrar
Using aregcmd, page Configuring a Basic Site, page
Configuring Cisco Access Registrar
Using aregcmd
General Command Syntax
aregcmd Commands
Configuring a Basic Site
Running aregcmd
set Password
Changing the Administrator’s Password
cd //localhost/Administrators
cd admin
add jane testadmin
Configuring the RADIUS Server
Creating Additional Administrators
cd /Administrators
Checking the Server’s Health
Checking the System-Level Defaults
set DefaultSessionManager
Selecting Ports to Use
add add ls
Displaying the UserLists
Step 1 Change directory to /Radius/Advanced/Ports
cd /Radius/Advanced/Ports
add jane
Displaying the Default UserList
Adding Users to UserLists
ls -R
Deleting Users
set password jane
cd /Radius/UserLists/Default delete beth
Displaying UserGroups
add QuickExampleNAS
Configuring Clients
Adding a NAS
cd /Radius/Clients
EnableNotifications TRUE
Configuring Profiles
Setting RADIUS Attributes
set IncomingScript ParseServiceHints EnableDynamicAuthorization TRUE
set Framed-Routing 192.168.1.0/24
Validating and Using Your Changes
Adding Multiple Cisco AV Pairs
Saving and Reloading
simple john john
Testing Your Configuration
Using radclient
radclient -s
p001 send
Configuring Accounting
Troubleshooting Your Configuration
Setting the Trace Level
aregcmd cd /Radius/Advanced/SNMP
Enabling SNMP in the Cisco Access Registrar Server
set Enabled TRUE
Stopping the Master Agent
4-15
Access Control
Modifying the snmpd.conf File
opt/CSCOar/bin/arserver stop
System Contact Information
Configuring Dynamic DNS
Restarting the Master Agent
Trap Recipient
cd ddns set Protocol dynamic-dns
cd /Radius/Advanced/DDNS/TSIGKeys add foo.com
cd foo.com set Secret base64-encoded string
cd /Radius/RemoteServers add ddns
cd /Radius/ResourceManagers add ddns
Testing Dynamic DNS with radclient
set IPAddress 10.10.10.1 ip address of primary dns server for zone
set ForwardZoneTSIGKey foo.com set ReverseZoneTSIGKey foo.com
set p acctrequest Start bob
cd /opt/CSCOar/bin aregcmd
trace Step 3 Launch radclient cd /opt/CSCOar/bin radclient
acctrequest Start username
OL-17221-02
4-20
Chapter 4 Configuring Cisco Access Registrar Configuring Dynamic DNS
Installing and Configuring Cisco Access Registrar
C H A P T E R
Customizing Your Configuration
Configuring Groups
Configuring Specific Groups
Object
Creating and Setting Group Membership
add PPP-users Users who always connect using PPP default-PPP-users
cd /Radius/UserLists/Default/jean
set AuthorizationScript AuthorizeService
Configuring a Default Group
Using a Script to Determine Service
cd /Radius/UserGroups/Default
reload
Configuring Multiple UserLists
set Group Default
save
Populating UserLists
Configuring Separate UserLists
Configuring Users
Creating Separate UserLists
cd /Radius/Services/North-users
Configuring Services
Creating Separate Services
cd /Radius/Services
cd /Radius
Configuring the Script
Client Scripting
Choosing the Scripting Point
Save tcl scripts in the directory /opt/CSCOar/scripts/radius/tcl
Configuring a Remote Server for AA
Handling Multiple Scripts
add ParseUserName Rex libParseUserName.so ParseUserName
add QuickExample
Configuring the Remote Server
Creating a RemoteServer
cd /Radius/RemoteServers
5-10
set UserPasswordAttribute password
set protocol ldap
set Port
5-11
Creating Services
add remote-ldap Remote LDAP Service
set type ldap
set DefaultAuthorization remote-ldap
Configuring Multiple Remote Servers
Changing the Authentication and Authorization Defaults
set DefaultAuthentication remote-ldap
5-13
Configuring Two Remote Servers
Creating RemoteServers
add North
set SharedSecret
Creating the Services
cd /Radius/RemoteServers/North
set protocol radius
Choosing the Scripting Point
set IncomingScript ParseRemoteServers
5-15
Configuring the Script
5-16
Configuring Session Management
Configuring a Resource Manager
Creating a Resource Manager
add rm-100
Configuring a Session Manager
Creating a Session Manager
cd /Radius/ResourceManagers
5-18
Configuring Session Management
Enabling Session Management
set 1 rm-100
I N D E
Symbols
IN-1
Failover policy
IN-2
Java 2 Platform
IN-3
IN-4